Skip to content
MLflowGHSA-vhcx-3pq2-4fvc

MLFlow path traversal vulnerability

Critical9.6CVE-2025-15036 · Published Mar 30, 2026 · updated Sep 10, 2026

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due to the lack of validation of tar member paths during extraction. An attacker with control over the tar.gz file can exploit this issue to overwrite arbitrary files or gain elevated privileges, potentially escaping the sandbox directory in multi-tenant or shared cluster environments.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 3.9.0rc03.9.0rc0
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-29
Also known as
BIT-mlflow-2025-15036, CVE-2025-15036, PYSEC-2026-425

More MLflow advisories

All MLflow
Advisory
MLflow: cross-site scripting
Medium5.4Apr 7
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
Medium4.3Apr 7
MLflow: remote code execution
Critical9.1Apr 3
Mlflow: Command Injection when serving models with enable_mlserver=True
Critical9.6Mar 31
MLflow Command Injection vulnerability
Critical10.0Mar 30
MLFlow allows Tracing + Assessments Access
High8.1Mar 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.